Why closings are the perfect target
A residential or commercial property closing has everything a wire fraud crew wants in one place: a large sum of money, a hard deadline, several parties who have never met in person, and instructions that arrive almost entirely by email. The buyer, the agency, the lawyer or notary and the bank each expect a message from one of the others at some point in the process, and none of them can easily verify a signature on a screen. Business Email Compromise, or BEC, is built for exactly this gap.
The FBI's Internet Crime Complaint Center calls BEC "the 55 billion dollar scam" in its most recent public update, tracking over 305,000 domestic and international incidents and more than 55 billion dollars in exposed losses between October 2013 and December 2023[1]. In 2024 alone, IC3 recorded 21,442 BEC complaints with 2.77 billion dollars in reported losses, and a further 9,359 complaints specifically coded as real estate fraud with 173.6 million dollars lost[2].
Real estate fraud losses have swung sharply year to year - 396.9 million dollars in 2022, down to 145.2 million in 2023, then back up to 173.6 million in 2024 - which IC3's own data suggests reflects changes in reporting and in how quickly banks intervene, not a shrinking problem[2]. For a small agency handling a handful of closings a month, a single successful redirection can be an existential loss, both financially and to the agency's reputation with the client whose deposit disappeared.
How the fraud actually runs
The pattern is consistent across the cases IC3 and European authorities describe, and it rarely starts with a dramatic hack. It starts with patience.
- 1Reconnaissance. The criminal monitors public listings, agency websites and sometimes a compromised mailbox to learn who is closing on what, and when. Real estate transactions are unusually public - the property, the rough timeline and often the agent's name are all findable with a search.
- 2Access or spoofing. Either the criminal compromises a real mailbox through a phishing email or a reused password, or they register a lookalike domain that differs from the real one by a single character or a swapped letter, and set up matching signatures and email threads.
- 3The pivot. At the point closest to the transfer - usually just before or during the closing window - the criminal sends new wiring instructions, styled to match prior correspondence, often citing a "change of bank" or an "urgent update from the title company."
- 4The transfer. The buyer, the agency's bookkeeper or the party responsible for moving funds wires the deposit or the full purchase amount to the criminal's account, frequently at a bank that acts only as a short-lived intermediary before the money is moved on or converted to cryptocurrency[1].
- 5The window closes fast. Funds are typically moved out of the receiving account within hours, which is why IC3 stresses that a victim's best chance of recovery depends on contacting their bank and filing a complaint within the first 24 to 72 hours[1].
ENISA's 2025 Threat Landscape report, drawn from an analysis of 4,875 recorded incidents across the EU, continues to place social engineering and email-based intrusion among the most consistently reported entry points into small and mid-sized organisations, which is precisely the profile of a local real estate agency[3].
The warning signs a closing team can actually catch
None of these require technical expertise. They require a habit of pausing before a transfer goes out.
- A last-minute change to bank details. Legitimate title companies, notaries and law firms almost never change their banking information mid-transaction. Any message that does should be treated as fraudulent until proven otherwise.
- Urgency and pressure language. "This must be sent today," "the seller is threatening to walk," or "please don't call, just confirm by email" are all classic pressure tactics designed to short-circuit verification.
- A domain that looks right at a glance. Watch for a swapped letter, an extra hyphen, or a different top-level domain from the one your agency and its partners actually use.
- A reply-to address that does not match the sender. Many BEC messages display a familiar name and address in the header but route replies to a different mailbox entirely.
- Requests to skip the usual process. Any instruction to bypass a callback, avoid a second signer, or wire funds outside normal banking hours is a signal to stop.
The controls that actually stop it
Email authentication. SPF, DKIM and DMARC, set up correctly and enforced (not just monitored), stop a large share of domain spoofing before it reaches an inbox. NIST's guidance on trustworthy email lays out exactly this stack as the baseline defence against forged sender addresses, and it is a configuration change, not new software, for agencies already on Microsoft 365 or Google Workspace[4].
Out-of-band verification for every payment instruction. Any change to wiring details must be confirmed by phone, using a number pulled from a previous, trusted document rather than one supplied in the suspicious email itself. This single habit defeats the overwhelming majority of BEC attempts, because the criminal cannot fake a phone call to a number they do not control.
A documented two-person rule for transfers. No wire above a set threshold should leave the agency's own systems, or be approved on behalf of a client, without a second person independently confirming the instruction against the original contract.
Multi-factor authentication on every mailbox. Most BEC cases that involve real account compromise, rather than pure spoofing, start with a stolen password on an account without MFA. Enforcing phishing-resistant MFA on every email account closes that door.
A written closing-day protocol shared with clients in advance. Tell buyers, in writing, before the transaction begins, that your agency will never change bank details by email and will never ask for funds to be sent to a new account without a verified phone call. That single sentence, sent early, gives a buyer the confidence to hang up on a fraudster and call your office instead.
What to do in the first hour if it happens anyway
Speed decides whether the money is recoverable. Contact the sending bank immediately and request a wire recall, and ask what documentation they need - policies vary by institution[1]. File a report with the relevant authority - IC3 in the United States, and the equivalent national police cybercrime unit or CERT in Israel, Greece or Spain - as soon as possible, because early reporting is what allows funds to be frozen before they are moved again[2]. Notify every party in the transaction chain in parallel, since the same criminal is very likely targeting the buyer, the seller and the notary with variations of the same message.
Frequently asked questions